> Ya but SAML supports sending the key in the metadata. There would be a trust if I could verify that the key is issued by a CA in the SignatureValidationFilter. So I take some random metadata, insert my key into it, sign it with that key and you'll trust it? Or am I missing something?